
Explore Cisco FirePower Threat Defense through hands-on labs on SMB topology, covering installation, network and routing, security policies and NAT, authentication and VPN, and home-lab setup with VMware workstation pro.
Explore the lab topology for a Cisco Firepower FTD setup featuring a firewall and switch, VLAN 16, 11, 12, Active Directory, web server, and ESXi VLAN groups.
Create ESXi vlan groups and a trunk port group for a sub interface, assigning vlans 200, 16, 10 (management), 11, and 12 with their subnets.
Install the Cisco Firepower Threat Defense virtual appliance on ESXi, configure management, WAN, and DMZ VLANs, set IPs and FTD-1 hostname, and enable standalone management via Firepower Device Manager.
Connect to the FirePower device manager, configure the outside interface, ntp, time zone, and licenses for a 90-day trial; explore the dashboard and set interface and routing for internet access.
Install and configure Cisco FirePower FTD on VMware Workstation Pro by importing the OVF and wiring management, WAN, inside, and DMZ interfaces to the correct VM nets.
Configure gigabit interface IPs and security zones for a FirePower FTD setup, assigning 0/0 to outside, 0/1 to inside, and 0/2 to DMZ, and create a DMZ zone.
Create two sub interfaces under Gigabit 0/3 for VLAN 11 and VLAN 12, assign 172.16.11.254/24 and 172.16.12.254/24, and deploy the changes to the firewall.
Configure dhcp server on the firewall to assign ip addresses for vlan 11 and vlan 12, using subnets 172.16.11.0 and 172.16.12.0 with dns 8.8.8.8.
Discover how to configure security policies by creating an inside-to-outside access rule for 172.16.0.0 and subnets 172.16.11.0 and 172.16.12.0, enable logging, deploy changes, and prepare to adjust the NAT rule.
Create auto nat rules for inside interface and VLANs 11 and 12, mapping 172.16.0.0 to the outside interface IP, add them to the inside zone, and verify internet access.
Configure a manual static NAT for a DMZ web server, translating 10.1.0.100 to 44.34.0.100, validate with show xlate and firewall logs to ensure internet access.
Enable ssl decryption on the firewall to decrypt and inspect https traffic using tls, activate the threat license, create a certificate, and apply decrypted re-sign rules excluding the finance category.
Configure a url filtering rule in the policy tab, set source inside and destination outside, select categories like adult and porn, and deploy with top-rule priority.
Create and deploy application filtering rules to allow Facebook access while blocking Facebook video and video chat, using inside source and outside destination zones, and verify via logs.
Enable malware and file blocking in the default file policy, ensure ssl decryption is active, deploy changes, and test with eicar files over https, confirming blocks via firewall logs.
Deploy IPS inspection by creating a test IPS policy, selecting intrusion mode, and applying it to the lan-to-wan rule to secure the network from attacks.
Enable security intelligence under policy tab to detect unwanted traffic by IP or URL, powered by Cisco Talos, drop traffic per access control policies, and expand the URL list.
Add an identity source using Active Directory to create user-based rules on the firewall, test the LDAP connection, and review users and groups in Active Directory for rule design.
Explore active authentication with a captive portal by configuring an identity rule, selecting the http response page, deploying to the firewall, and validating user login and log visibility.
Configure a site-to-site vpn between Istanbul and Ankara, use policy-based ipsec with a pre-shared key, set static routes, and create traffic rules to enable inter-subnet communication.
Configure ftd admin access by managing management and data interfaces in system settings, restrict access via ip subnets using the plus button, and create data interfaces with 192.168.10.201 and 172.16.0.254.
Learn to implement high availability by adding a second firewall, configuring active and standby devices, and ensuring seamless failover and synchronization of settings across devices.
Set up automatic and manual backups for your firewall, name backups, enable encryption, download and save the files, then restore by uploading to your firewall or a new device.
!!! YOU CAN GET DISCOUNT CODES FOR ALL MY TRAININGS FROM MY WEBSITE !!!
In this training, you can learn Cisco FirePower Threat Defense (FTD) firewall installation and management through the sample topology that you can apply in small and medium-sized companies. Cisco is one of the leading Network products manufacturer in the world, and you can always be one step ahead in the industry by learning the installation and management of Cisco products.
During the training, we will install and manage our Firewall standalone by using Cisco FirePower Device Manager for all our lab work. First, we will prepare the vLAN on VmWare, then we will install the Cisco FirePower Threat Defense Firewall, after the installation, we will start to manage our device by making our basic settings and interface settings.
Throughout our education; Nat , SSL Decryption, URL Filtering, Application Filtering, Malware and File Blocking , Security Intelligence, IPS Inspection, Identity Sources and Identity Active Authentication (Captive Portal), IPsec Site to Site VPN, High Availability (HA), Back Up and Restore We will cover many more topics.
To participate in the training, you must have basic system, network and firewall knowledge. I also recommend that you have received Cisco CCNA training. This training will also help you prepare for the Cisco CCNP Security exam.
This training is suitable for anyone who wants to improve themselves in Network and Cyber Security.
I tried to convey this training to you in the best way with my 24 years of experience in the sector. I had a lot of fun while preparing the training, I have no doubt that you will enjoy watching it too.
In order to provide you with the best sound and image quality, I used a quality microphone and HD camera while shooting.